PT-2022-21966 · WordPress · The Bricks

Published

2022-10-28

·

Updated

2022-11-03

·

CVE-2022-3401

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Bricks theme for WordPress versions 1.2 to 1.5.3
Description The issue allows remote code execution due to the theme permitting site editors to include executable code blocks in website content. This is exacerbated by a missing authorization vulnerability, enabling authenticated attackers with minimal permissions to edit pages, posts, or templates and inject code execution blocks for remote code execution.
Recommendations For versions 1.2 to 1.5.3, update to a version that fixes the remote code execution and missing authorization vulnerabilities. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-3401

Affected Products

The Bricks